goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is fixed in 2.0.0-beta.3.
Attack Parameters
Impact Assessment
CVSS Vector v3.0
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Goshs Goshs
cpe:2.3:a:goshs:goshs:*:*:*:*:*:go:*:*
|
— |
2.0.0
|
|
Goshs Goshs
cpe:2.3:a:goshs:goshs:2.0.0:beta1:*:*:*:go:*:*
|
— | — |
|
Goshs Goshs
cpe:2.3:a:goshs:goshs:2.0.0:beta2:*:*:*:go:*:*
|
— | — |